# Exclude user access using regular expressions in kibana

**URL:** <https://discuss.elastic.co/t/exclude-user-access-using-regular-expressions-in-kibana/322833>\
**Category:** Kibana\
**Created:** [January 10, 2023, 12:37pm UTC](https://discuss.elastic.co/t/exclude-user-access-using-regular-expressions-in-kibana/322833 "2023-01-10T12:37:18Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Shivani\_Hadke](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shivani_hadke/32/100359_2.png) [@Shivani\_Hadke](https://discuss.elastic.co/u/Shivani_Hadke)\
**Post date:** [January 10, 2023, 12:37pm UTC](https://discuss.elastic.co/t/exclude-user-access-using-regular-expressions-in-kibana/322833/1 "2023-01-10T12:37:18Z")

</div>

I would like to exclude only a particular index and have access to rest of all indexes in a cluster.

Right now, I'm adding every index by clicking on it and in roles and it is a hectic task to do just to exclude one index in the permissions.

Is there a way I can do this excluding using regular expressions. If yes, can I give it in kibana roles?

Thanks in advance.

Please guide me to find a solution.

---

<div class="post-metadata">

**Author:** ![dadiasish](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadiasish/32/114221_2.png) [@dadiasish](https://discuss.elastic.co/u/dadiasish)\
**Post date:** [January 10, 2023, 12:40pm UTC](https://discuss.elastic.co/t/exclude-user-access-using-regular-expressions-in-kibana/322833/2 "2023-01-10T12:40:38Z")

</div>

Hi,

Yes there is a possibility. Go through the below documentation for reference.

> **[Regular expression syntax | Elasticsearch Guide \[8.5\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/regexp-syntax.html)**

```auto
`ANYSTRING`

Enables the `@` operator. You can use `@` to match any entire string.

You can combine the `@` operator with `&` and `~` operators to create an "everything except" logic. For example:

@&~(abc.+) # matches everything except terms beginning with 'abc'

```

You can use the below format in Dev Tools to exclude only a particular regex and give access to rest all.

```auto
{
  "cluster": ["all"],
  "indices": [
    {
      "names": ["/@&~(abcde.+)/"],
      "privileges": ["all"],
      "allow_restricted_indices" : false
    }
  ]

```

In names, give the index name in place of "abcde" and only that index is excluded to access.

---

<div class="post-metadata">

**Author:** ![Shivani\_Hadke](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shivani_hadke/32/100359_2.png) [@Shivani\_Hadke](https://discuss.elastic.co/u/Shivani_Hadke)\
**Post date:** [January 10, 2023, 12:44pm UTC](https://discuss.elastic.co/t/exclude-user-access-using-regular-expressions-in-kibana/322833/3 "2023-01-10T12:44:04Z")

</div>

Do I need to do this in dev tools?

Should I directly give this. Sorry please guide me as I'm new in doing this.

It would be great if you provide me with an example.

---

<div class="post-metadata">

**Author:** ![dadiasish](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadiasish/32/114221_2.png) [@dadiasish](https://discuss.elastic.co/u/dadiasish)\
**Post date:** [January 10, 2023, 12:45pm UTC](https://discuss.elastic.co/t/exclude-user-access-using-regular-expressions-in-kibana/322833/4 "2023-01-10T12:45:12Z")

</div>

This is just an example, you need to alter according to your requirement on what you need to enable in the access.

Below is an example:

```auto
POST _security/role/sample_role
{
  "cluster": ["all"],
  "indices": [
    {
      "names": ["/@&~(abcde.+)/"],
      "privileges": ["all"],
      "allow_restricted_indices" : false
    }
  ],
  "applications" : [
      {
        "application" : "kibana-.kibana",
        "privileges" : [
          "feature_discover.all",
          "feature_dashboard.all",
          "feature_canvas.all",
          "feature_maps.read",
          "feature_visualize.all",
          "feature_logs.all",
          "feature_infrastructure.all",
          "feature_apm.read",
          "feature_uptime.all",
          "feature_siem.read",
          "feature_dev_tools.all",
          "feature_advancedSettings.read",
          "feature_indexPatterns.all",
          "feature_savedObjectsManagement.read",
          "feature_fleet.all"
        ],
        "resources" : [
          "space:default"
        ]
      }
    ],
    "run_as" : [],
    "metadata" : { },
    "transient_metadata" : {
      "enabled" : true
    }
}

```

---

<div class="post-metadata">

**Author:** ![Shivani\_Hadke](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shivani_hadke/32/100359_2.png) [@Shivani\_Hadke](https://discuss.elastic.co/u/Shivani_Hadke)\
**Post date:** [January 10, 2023, 12:45pm UTC](https://discuss.elastic.co/t/exclude-user-access-using-regular-expressions-in-kibana/322833/5 "2023-01-10T12:45:45Z")

</div>

Thanks a lot. Let me try.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 7, 2023, 12:46pm UTC](https://discuss.elastic.co/t/exclude-user-access-using-regular-expressions-in-kibana/322833/6 "2023-02-07T12:46:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
